CVE-2019-25613: Echatserver Easy Chat Server
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
Easy Chat Server 3.1 contains a denial of service vulnerability that allows remote attackers to crash the application by sending oversized data in the message parameter. Attackers can establish a session via the chat.ghp endpoint and then send a POST request to body2.ghp with an excessively large message parameter value to cause the service to crash.
Affected products
- Echatserver Easy Chat Server: version 3.1 only
Published 2026-03-22. Last modified 2026-06-17.